NEW
Font size
Worksheetslast22
Total questions: 22
Worksheet time: 11mins
HIDS differs from NIDS in what manner?
One is "high" IDS and the other is "normal"
One is "host" IDS and the other is "normal"
One is "homogeneous" IDS and the other is "network"
They are the same thing
None of the above
The biggest challenge to signature-based security for detecting malware is which of the following?
Difficulty in keeping the lists readable
Difficulty in managing more than one list
Behavioral anomalies
Variants
All of the above
Which of the following is a false statement regarding SIEMs?
A SIEM will not work with proper crypto
SIEM security requires network tunnels
SIEMS always require SOCs
SOCs typically use SIEMS
All the above
Which of the following is a true statement?
Perimeter protection works great on enterprise networks
Perimeter protection works poorly on enterprise networks
Perimeters work unless mobility is present
Cloud requires perimeter protection
All of the above
Automation in a SOC is a good idea for which of the following?
It is a mandatory requirement in most compliance frameworks
It requires 24 by 7 operation
It is already done in other parts of the enterprise
It reduces response cycle times
None of the above
Which of the following is a true statement?
IDS = IPS
SIEM = SOC
IDS is implied by IPS
SOC is implied by SIEM
All of the above
The malicious client is sending a massive flood of SYN packets to the web server. Which of the following security mitigations choices (or none) is best for the web server administrator to employ to reduce the risk of this attack:
Increased application-level authentication of the client
Running a scan on the web server for vulnerabilities
Implementing improved auditing on both the client and server
None of the above.
The malicious client is sniffing packets on the local LAN to detect any local activity of interest. Which of the following security mitigations would be best for the administrator of the local LAN to employ to reduce the risk of the malicious client inappropriately obtaining information from other LAN users:
Warnings to users to be careful
LAN encryption
Physical security of LAN equipment
None of the above
The malicious client is sending a massive number of spoofed packets to the web server, resulting in response SYN/ACK packets being sent to the spoofed address, perhaps causing a flood condition for that system. Which of the following security mitigations would be best employed on the web server to deal with the massive number of spoofed packets:
Running an IPS in front of the server to shun the spoofed source
Running a DOS defense service in front of the web server that detects the flood of spoofed sources
Notifying the spoofed IP address of the incident
All of the above
The malicious client is repeatedly trying to use administrative commands to log into the web server. Which of the following security mitigations would be best for the:
Positioning a firewall in front of the server to filter commands
Improving the strength of administrative passwords
Running an IDS in front of the server to detect attacks
All of the above
The malicious client is using a powerful scanning tool to launch scans against the web server. Which of the following security mitigations would be best for the administrator of the web server employ to reduce the risk of the scan:
Minimizing the inbound network capacity
Minimizing the inbound services
Maximizing encryption on all ports
None of the above
The malicious client recruits a botnet and launches a massive DDOS attack using a target DNS server that is sent requests spoofed as coming from the web server. Which of the following security mitigations would be best for the DNS administrator to consider using to reduce the risk of this attack:
Do not respond to the DNS requests
Demand that tunneling protocols be used for all DNS requests
Turn on auditing so that records of attacks are available
None of the above.
Perimeters exhibit which of the following weaknesses?
Clash between management and audit
Weak performance
Too many rules
Too few policy controls
All of the above
Advanced persistent threats (APTs) exfiltrate data through which of the following weaknesses?
Open gateway access to the Web
Open remote access into the LAN
Open source software reviews
Hacking conference discussions
None of the above
Third party security is best accomplished through which of the following?
Contracts
Service level agreements
Monitoring
Vetting
All of the above
DDOS attacks at layer 3 are characterized by which of the following?
Weak encryption
Volume
Efficiency of payload
Tagged labels
All of the above
Which of the following techniques reduce DDOS risk?
Protocol redesign
Network traffic obscuring
Network traffic redirection
All of the above
Which is the following is a true statement?
DDOS targets spoofed targets
DDOS never involves spoofed sources
DDOS might involve spoofed targets
DDOS might involve spoofed sources
All of the above
Third party attacks are tough to mitigate for which of the following reasons?
Attacks are distributed
Attacks are centralized
Attacks are based on vulnerabilities
Vulnerabilities are tough to manage remotely
All of the above
APTs are best mitigated through which of the following techniques?
Architectural improvement
Policy improvement
Procedural improvement
All of the above
Perimeter security exhibits which of the following?
Standards-based protection
Effective mitigation of insiders
Good protection against APT
None of the above
Which of the following is not a true statement?
DDOS attacks will increasingly involve cloud
DDOS attacks will increasingly involve mobility
DDOS attacks will grow in an unbounded manner
DDOS attacks will increasingly involve IoT
None of the above
